Skip to content
TrustList
News

GROWI wiki before 7.5.5 lets anyone read files on private pages

Editorial

By TrustList Editorial

Only installations that store uploads locally are exposed. JPCERT/CC rates the flaw 6.9 on the CVSS 4.0 scale, and the vendor has released version 7.5.5 with the fix.

About GROWI wiki before 7.5.5 lets anyone read files on private pages

GROWI wiki before 7.5.5 lets anyone read files on private pages

5 October 2026: GROWI, the open-source wiki that Japanese teams use for internal documentation, has an access-control flaw that lets a remote, unauthenticated attacker read files attached to non-public pages. Versions before 7.5.5 are affected, and 7.5.5 contains the fix, according to an advisory published on Japan's JVN vulnerability portal.

Not yet independently verified. Single source: the JVN advisory, which is based on the vendor's report to JPCERT/CC. We have not read the vendor's own release notes. We will update this when it can be confirmed, and remove this note.

The flaw is tracked as CVE-2026-100727 and classed as CWE-552, files or directories accessible to external parties. JPCERT/CC lists a CVSS 4.0 base score of 6.9 and a CVSS 3.0 score of 5.3. Both reflect a network attack that needs no privileges and no user interaction, with a limited loss of confidentiality and no effect on integrity or availability.

Not every installation is exposed. The advisory says the product is affected only when the file upload setting is configured as "Local". Deployments that store uploads in an external object store rather than on the application server are therefore not described as vulnerable.

The advisory was published on 5 October. GROWI, Inc. reported the vulnerability itself to JPCERT/CC, which coordinated the disclosure with the company under Japan's Information Security Early Warning Partnership, so the notice reflects a vendor-led fix rather than an outside discovery. JVN lists the vendor's status as vulnerable, last updated on the same day.

The practical risk is about attachments, which in a team wiki often hold contracts, screenshots of internal systems and exported spreadsheets. Because the flaw works without a login, a wiki reachable from the internet is more exposed than one limited to a company network. Administrators should check whether uploads are set to Local and update to 7.5.5 or later. The advisory describes no workaround other than updating.

Company profile on TrustList: GROWI

Sources

Categories & features

TrustList Weekly

The week in software and IT, in one email

The news that matters to buyers, new rankings and our own research. Every Thursday, free, and easy to leave.

We will email you to confirm. Unsubscribe with one click in any issue. Privacy policy